North Korea-Linked Hacking Group Stole $10.7 Million from Crypto and AI Recruitments
A North Korean hacking group known as WaterPlum has stolen at least $10.7 million by posing as recruiters for cryptocurrency and artificial intelligence companies. The group targeted software developers and information technology professionals worldwide, infecting at least 30,000 devices in over 100 countries.
WaterPlum approached victims through social media, online job sites, and freelance platforms, persuading them to run malicious files disguised as coding tests or software meant to fix video-conferencing problems. The attackers used remote-access trojans and information-stealing malware to take sensitive data and crypto assets.
The group's activities have been linked to North Korea's strategy of infiltrating overseas IT workforces, with authorities in Japan and the US believing members of WaterPlum operate under North Korea's Munitions Industry Department. The stolen personal data could be used by North Korean IT workers to disguise their identities or earn income from overseas companies.